UK supplier due diligence, without the false confidence.
UK buyers routinely ask suppliers for ISO 27001, Cyber Essentials, and UK GDPR / Data Protection Act 2018 evidence. Keepgrade gives UK small and midsize organisations a continuous AI readiness copilot between formal engagements — a 15-minute readiness score across the framework mix, the per-domain gap map, and the assessor routing when you are ready to certify or attest.
ISO 27001 supplier asks
Major UK buyers — finance, healthcare, critical infrastructure — request ISO 27001 evidence or a credible readiness narrative. The certificate is issued by an accredited certification body; a self-attested readiness score cannot grant it.
Cyber Essentials for public-sector suppliers
Government and NHS-linked procurements frequently require Cyber Essentials or Cyber Essentials Plus. The scheme is administered by IASME on behalf of NCSC; readiness scoring supports the application, but does not issue the badge.
UK GDPR / DPA 2018 evidence asks
Buyers and Data Protection Officers request Article 30 records of processing, DPIAs, and breach-notification evidence. UK GDPR is a regulatory floor enforced by the ICO, not a certifiable framework — readiness scoring surfaces where the evidence gaps are.
ISO 27001:2022
Certification
The certificate is issued by an accredited certification body after a Stage 1 (readiness review) and Stage 2 (on-site audit) process. Keepgrade's readiness score is the self-attested groundwork that prepares you for the audit — never the certificate itself.
Cyber Essentials
Voluntary scheme (NCSC-aligned)
Administered by IASME on behalf of the National Cyber Security Centre. Basic and Plus tiers differ in the verification model (self-answered questionnaire vs hands-on technical audit). Readiness scoring supports the application and surfaces what would fail the Plus technical check.
UK GDPR / Data Protection Act 2018
Regulatory framework (ICO)
A regulatory floor enforced by the Information Commissioner's Office, not a certifiable framework. Readiness scoring surfaces Article 30 records of processing, DPIA coverage, and breach-notification readiness gaps against the regulation.
Stage 1
Run a 15-minute readiness score
Pick ISO 27001 or SOC 2 from the framework picker, answer the same twelve NIST-CSF-functions-tagged questions, and leave with a per-domain 0..100 score and band. The instrument is the same one our deeper engagements are grounded against.
Stage 2
Review the per-domain gap map
See exactly where ISO/CE/UK-GDPR evidence asks are uncovered — Annex A control families, the NCSC Cyber Essentials technical themes, or Article 30 / DPIA evidence gaps. The next 30 minutes of hardening effort is obvious from the gap map.
Stage 3
Route to the right UK-aligned assessor
When the band is ready, the assessor marketplace routes you to a UK-appropriate assessor type — accredited ISO certification bodies, Cyber Essentials certification bodies, ICO-ready UK DPOs, or AICPA SOC auditors for transatlantic SaaS.
A readiness score is a self-attested readiness number against a published control set. The number answers one question: how ready is the org to pass the authoritative audit / attestation / assessment for this framework? We compute the number once on every submission using a deterministic + AI-validated scoring engine, then surface it with a band and a per-domain gap map so the next 30 minutes of hardening effort is obvious.
For UK journey buyers, that distinction matters: a readiness score of 78 against ISO 27001 tells you you are ready to commission a Stage 1 + Stage 2 audit — the certificate itself is still issued by an accredited certification body. A readiness score of 0..100 against UK GDPR tells you which Article 30 records and DPIAs are missing — it does not demonstrate compliance to the ICO.
Run a readiness score before the next buyer questionnaire lands.
Fifteen minutes, no signup, a per-domain score and band against ISO 27001 or SOC 2 — and a clear next move when the band is ready. See plans and bespoke Remix engagements in pricing.